[grade=B] fix(auth): reuse valid session for cross-host SSO
This commit is contained in:
Vendored
+77
-77
File diff suppressed because one or more lines are too long
+42
-2
@@ -267,6 +267,42 @@
|
||||
}
|
||||
}
|
||||
|
||||
function buildSsoHandoffTarget(returnUrl, token) {
|
||||
const parsed = new URL(returnUrl, window.location.origin);
|
||||
if (parsed.origin === window.location.origin) return parsed.toString();
|
||||
|
||||
const suffix = SITE.tld.startsWith('.') ? SITE.tld : `.${SITE.tld}`;
|
||||
const isPrivateHost = parsed.hostname === suffix.slice(1) || parsed.hostname.endsWith(suffix);
|
||||
if (parsed.protocol !== 'https:' || !isPrivateHost || !token) return null;
|
||||
|
||||
const returnPath = `${parsed.pathname}${parsed.search}${parsed.hash}`;
|
||||
parsed.pathname = '/dashcaddy-sso';
|
||||
parsed.search = '';
|
||||
parsed.hash = '';
|
||||
parsed.searchParams.set('token', token);
|
||||
parsed.searchParams.set('return', returnPath);
|
||||
return parsed.toString();
|
||||
}
|
||||
|
||||
async function resumeExistingSession(returnUrl) {
|
||||
if (!returnUrl || !isAllowedReturnUrl(returnUrl)) return false;
|
||||
try {
|
||||
const res = await fetch('/api/v1/auth/sso-handoff', {
|
||||
credentials: 'include',
|
||||
cache: 'no-store',
|
||||
});
|
||||
if (!res.ok) return false;
|
||||
const data = await res.json();
|
||||
const target = data.success && buildSsoHandoffTarget(returnUrl, data.ssoToken);
|
||||
if (!target) return false;
|
||||
try { sessionStorage.removeItem('totp_redirect'); } catch (_) {}
|
||||
window.location.replace(target);
|
||||
return true;
|
||||
} catch (_) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
const urlParams = new URLSearchParams(window.location.search);
|
||||
if (urlParams.get('auth') === 'required') {
|
||||
// Preserve the gated service destination so submitTotpCode() can append
|
||||
@@ -277,8 +313,12 @@
|
||||
}
|
||||
// Clean URL — happens after we've captured the redirect
|
||||
window.history.replaceState({}, '', window.location.pathname);
|
||||
// Show on next tick so the DOM (the .totp-card) is ready
|
||||
setTimeout(show, 0);
|
||||
// Reuse the valid status.sami session first. Only show the TOTP/provider
|
||||
// challenge when that session is genuinely absent or expired.
|
||||
setTimeout(async () => {
|
||||
if (await resumeExistingSession(returnUrl)) return;
|
||||
await show();
|
||||
}, 0);
|
||||
}
|
||||
|
||||
// Expose for hot-trigger from other modules (e.g. logout)
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
const CACHE = 'dashcaddy-shell-a24ef15882';
|
||||
const CACHE = 'dashcaddy-shell-5dbd809d3b';
|
||||
const PRECACHE = [
|
||||
'/',
|
||||
'/index.html',
|
||||
|
||||
@@ -93,3 +93,41 @@ test('same-origin and tokenless destinations keep their direct URL', () => {
|
||||
assert.equal(buildHandoffTarget('/settings', 'one-time'), 'https://status.sami/settings');
|
||||
assert.equal(buildHandoffTarget('https://router.sami/config', ''), 'https://router.sami/config');
|
||||
});
|
||||
|
||||
test('an existing status.sami session returns to a service without another TOTP prompt', async () => {
|
||||
const query = new URLSearchParams({ auth: 'required', return: 'https://plex.sami/web/' });
|
||||
let scheduled;
|
||||
let redirected;
|
||||
const location = {
|
||||
origin: 'https://status.sami',
|
||||
pathname: '/',
|
||||
search: `?${query.toString()}`,
|
||||
replace(value) { redirected = value; },
|
||||
};
|
||||
const context = {
|
||||
URL,
|
||||
URLSearchParams,
|
||||
SITE: { tld: '.sami' },
|
||||
sessionStorage: { setItem() {} },
|
||||
document: { getElementById() { return null; } },
|
||||
setTimeout(fn) { scheduled = fn; },
|
||||
console,
|
||||
fetch: async (url) => {
|
||||
assert.equal(url, '/api/v1/auth/sso-handoff');
|
||||
return { ok: true, json: async () => ({ success: true, ssoToken: 'existing-session-token' }) };
|
||||
},
|
||||
window: {
|
||||
location,
|
||||
history: { replaceState() {} },
|
||||
},
|
||||
};
|
||||
context.window.window = context.window;
|
||||
vm.runInNewContext(source, context, { filename: 'auth-gate.js' });
|
||||
|
||||
assert.equal(typeof scheduled, 'function');
|
||||
await scheduled();
|
||||
assert.equal(
|
||||
redirected,
|
||||
'https://plex.sami/dashcaddy-sso?token=existing-session-token&return=%2Fweb%2F',
|
||||
);
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user